Input Validation Flaw in Logpoint Threat Intelligence
CVE-2024-33857

Currently unrated

Key Information:

Vendor

Logpoint

Status
Vendor
CVE Published:
7 May 2024

What is CVE-2024-33857?

A vulnerability affecting Logpoint prior to version 7.4.0 arises from inadequate input validation of URLs in the threat intelligence module. This security flaw allows an attacker with minimal access to execute Server Side Request Forgery (SSRF), potentially leading to unauthorized access or manipulation of internal services. By exploiting this weakness, the attacker may craft malicious requests that pose risks to the sensitive data and operational integrity of affected systems.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-33857 : Input Validation Flaw in Logpoint Threat Intelligence